Data Subject Rights
Principles
Obligations & Enforcement
Fun facts
Definitions & Key Terms
100

This right allows you to find out if a company has your personal information and get a copy of it.

What is the right to access?

100

Collecting only the data you need is an example of this privacy principle.

What is data minimization?

100

Under the JDPA, this is the regulator that oversees compliance in Jamaica.

What is the Information Commissioner?

100

This is the month many countries celebrate Data Privacy Day.

What is January?


100

An individual whose personal data is processed is called this.

What is a Data Subject?

200

The JDPA and GDPR both allow you to request corrections to inaccurate information with this right.

What is the right to rectification?

200

Under both acts, organizations should only hold personal data for as long as this.

What is necessary (storage limitation)?

200

Under GDPR, organizations may have to appoint this role to oversee privacy compliance.

What is a Data Protection Officer (DPO)?

200

The organization that determines why and how data is processed.

What is a Data Controller?

300

You can ask a company to delete your data in certain circumstances using this right, sometimes called “the right to be forgotten.”

What is the right to erasure?

300

Keeping data accurate and up to date reflects this GDPR and JDPA principle.

What is accuracy?

300

This document, required under both laws, outlines how an organization processes personal data.

What is a Privacy Notice/Privacy Policy?

300

What does the acronym ‘GDPR’ stand for?

What is General Data Protection Regulation?

300

This word describes information relating to an identified or identifiable person.

What is Personal Data?

400

This right lets you object to your data being used for marketing.

What is the right to object (to processing for direct marketing)?

400

The obligation to be open and honest about what you do with people's data is known as this.

What is transparency?

400

These must be carried out when new technology or procedures could threaten people’s privacy.

What are Data Protection Impact Assessments (DPIAs)?

400

This means any operation performed on personal data, like collecting, storing, or deleting it.

What is Processing?

500

Under both laws, you can ask organizations to stop processing your data temporarily using this right.

What is the right to restrict processing?

500

Organizations must ensure appropriate security to prevent unauthorized access to data, called this principle.

What is integrity and confidentiality (security)?

500


Within this time frame, breaches must be reported to authorities under GDPR/ JDPA.

What is 72 hours?

500

Why can’t privacy laws throw surprise parties?

Because they always require prior consent!

500

This is required to process sensitive personal data under both GDPR and JDPA.

What is Explicit Consent?